You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用GitHub API v3添加协作者:请求pull权限却获Write权限问题

GitHub API 添加协作者时权限设置不生效(pull 被设为 Write)

我碰到了一个问题:用GitHub API v3的协作者端点添加协作者,明明指定了pull权限,结果对方却拿到了Write访问权限,完全不是我想要的Read权限。我原本理解的权限对应关系是:

pull: read
push: write
admin: admin

下面是我在Django里使用的代码:

# Add the person as a collaborator
r = requests.put(
    'https://api.github.com/repos/' + \
    github_repository['owner']['login'] + \
    '/' + \
    github_repository['name'] + \
    '/collaborators/' + \
    github_username,
    params = {
        'permission': 'pull',
    },
    auth = [ ...auth... ],
)

问题原因&解决方案

问题出在传递permission参数的方式上!GitHub的这个API端点要求权限参数必须放在请求体里,而不是URL的查询参数(也就是你代码里的params)。当你用params传的时候,API会直接忽略这个参数,然后使用默认权限——默认就是push(对应Write),这就是为什么结果不符合预期。

修改代码,把permission移到json参数里(requests的json参数会自动把数据序列化成JSON请求体发送):

# Add the person as a collaborator
r = requests.put(
    'https://api.github.com/repos/' + \
    github_repository['owner']['login'] + \
    '/' + \
    github_repository['name'] + \
    '/collaborators/' + \
    github_username,
    json = {
        'permission': 'pull',
    },
    auth = [ ...auth... ],
)

这样修改后,协作者就会被正确赋予Read权限了。另外补充下,这个端点支持的权限值除了pull、push、admin,如果是组织仓库的话,还支持maintain和triage哦。

内容的提问来源于stack exchange,提问作者Apollo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 10:13:40